Impact
The Windows Program Compatibility Assistant Service logs sensitive data during routine operations. An attacker with local privileges can trigger the logging of confidential information, thereby exposing it via log files. This results in confidential data being disclosed to the attacker. The weakness corresponds to improper log handling (CWE-532) and inadequate data sanitization (CWE-908).
Affected Systems
Microsoft Windows 11 versions 23H2, 24H2, 25H2, and 26H1, as well as Microsoft Windows Server 2025—including Server Core installations—are affected. These versions run the Program Compatibility Assistant Service that incorrectly records sensitive data in system logs.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate risk. The vulnerability is exploitable by an attacker who already has local access; no remote exploitation path is described, and the EPSS score is unavailable. The vulnerability is not listed in the CISA KEV catalog. An authorized local user could read the log files and obtain sensitive information without affecting system integrity or availability.
OpenCVE Enrichment